Release date:
Updated on:
Affected Systems:
PHP 5.5.x
PHP 5.4.x
PHP 5.3.x
Description:
--------------------------------------------------------------------------------
Bugtraq id: 64225
CVE (CAN) ID: CVE-2013-6420
PHP is an embedded HTML language.
When parsing x.509 certificates in PHP versions earlier than 5.3.27, 5.4.22, and 5.5.6, the "asn1_time_to_time_t ()" function (ext/openssl. c) an error occurs. Attackers exploit this vulnerability through a specially crafted x.509 Certificate to destroy the memory.
<* Source: Stefan Esser (s.esser@ematters.de)
Link: http://secunia.com/advisories/56055/
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
PHP
---
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.php.net
Http://www.php.net/downloads.php
Http://git.php.net /? P = php-src.git; a = commitdiff; h = c1224573c773b6845e83505f717fbf820fc18415
Http://git.php.net /? P = php-src.git; a = blobdiff; f = NEWS; h = Beijing; hp = Beijing; hb = Beijing; hpb = 32873cd0ddea7df8062213bb025beb6fb070e59d